Avast Blog_Tips & Advices: The truth about single sign-on (SSO)
#1
Lightbulb 
Quote:
[Image: sso.jpg]

SSO saves you headaches, but is it secure enough to hold all your secrets?

Do you ever “log in with Google” or “log in with Facebook” to access an account that’s not either of those two? If so, you have used single sign-on (SSO), and you probably chose that option because it saved you from having to create and remember yet another password for yet another account. That’s precisely the point of SSO — it’s a remedy for password fatigue. 

The history of SSO

According to Forbes, SSO was invented in the late 1980’s as an identity and access management system (IAM) to help companies and government agencies consolidate all their employees’ login credentials into a single infrastructure. The workforce was beginning to go digital, and employers quickly saw a problem when their workers started keeping track of their multiple passwords on post-in notes around their desks. 

SSO simplified the process tremendously. Not only did it provide the convenience of a single authentication that unlocked multiple applications, but the reverse was also true – it was a one-stop shop to revoke all the privileges of an employee leaving the company. This was especially helpful to large enterprises where workers used dozens of applications. 

Today, people are juggling more passwords than ever, and SSO options have become ubiquitous. Users like to choose SSO because it’s less of a headache, and websites like to offer SSO because it reduces user friction, the degree of effort a user must put forth to access a site or app. 

The convenience of SSO is plain to see — but how secure is it? Some worry that SSO is vulnerable because, while brilliantly convenient, it is also all-inclusive of your online secrets. If one bad actor gets your SSO credentials, your entire digital life opens to them. Additionally, privacy advocates note that by using Google or Facebook to log into a third-party site, it provides those internet giants with more of your metadata and digital footprint

FIDO's role in SSO

Enter the FIDO Alliance, an open industry association made up of over 200 companies and government agencies with a mission to “solve the world’s password problem.” The group’s website claims that passwords are the root cause of over 80% of data breaches. Its solution? Get rid of the passwords. 

FIDO developed an SSO that uses password-less authentication. Instead of a typed credential, it relies on biometrics like your fingerprint, your face, or your voice. It also offers second-factor authentication in the form of a security key that you plug into your device or computer. These methods mitigate many hacking tricks like credential stuffing, dictionary attacks, keystroke logging, and more. FIDO realized that the best way to authenticate a person is to use the actual person instead of an alphanumeric code that anyone could enter. 

As we move forward, this technology is only going to get more sophisticated. As we give hackers less opportunity to spoof our identities, we gain more control over our digital lives. For now, if you still use passwords, make sure you’re not reusing any across multiple accounts. And if you use SSO, protect that all-important authentication with two-step or multi-step verification.
...
Continue Reading
Reply


Forum Jump:


Users browsing this thread: 1 Guest(s)
[-]
Welcome
You have to register before you can post on our site.

Username/Email:


Password:





[-]
Recent Posts
Surfshark VPN : Award-winning VPN servi...
Surfshark Apps Ver...jasonX — 04:41
Surfshark VPN : Award-winning VPN servi...
Surfshark launches...jasonX — 03:43
ESET 19.1.12.0
Changes in 19.1.12...harlan4096 — 14:49
Vivaldi 7.9 Build 3970.47
Vivaldi 7.9 Build ...harlan4096 — 07:31
Microsoft Defender Antivirus security in...
Stable channel upd...harlan4096 — 07:25

[-]
Birthdays
Today's Birthdays
avatar (41)alapesihy
Upcoming Birthdays
avatar (45)wapedDow
avatar (49)oapedDow
avatar (42)Sanchowogy
avatar (46)MeighGoask
avatar (47)creatralGuelm
avatar (38)procnipsut
avatar (44)accenwibly
avatar (41)ahyvily
avatar (38)urumahiz
avatar (44)techlignub
avatar (43)Stevenmam
avatar (50)onlinbah
avatar (50)fuspeukChark
avatar (44)werriewWaiNg
avatar (38)Freemanleo
avatar (48)cticigges
avatar (50)ecoFit
avatar (44)soccejeS
avatar (43)cdoubapKit
avatar (38)lystraPonia
avatar (31)smith8395john
avatar (51)steakelask
avatar (45)Termoplenka
avatar (43)bycoPaist
avatar (49)pieloKat
avatar (43)ilyagNeexy
avatar (51)donitascene
avatar (51)burntLaw
avatar (41)MrDoorsskibheeds
avatar (51)Toligo
avatar (46)Rodneykak
avatar (49)tradeSmode
avatar (39)vemedProkbior
avatar (38)RobertUtelt
avatar (46)JamesZic
avatar (43)Sanfordbup
avatar (38)Der.Reisende
avatar (36)Kiran78

[-]
Online Staff
There are no staff members currently online.

>